MCP Atlassian Vulnerabilities

pip AI Agents

AI Threat Alert tracks 39 known vulnerabilities in MCP Atlassian, 3 rated critical — an AI/ML ai agents in the pip ecosystem. Each CVE includes CVSS severity, EPSS exploit probability, patch status, and CISO-grade analysis.

Data sources
45
Risk Score
39
Total CVEs
3
Critical
pip
Ecosystem
Sep 22, 2026
Last CVE
85%
Patch Rate
4d
Avg Time to Patch

Known Vulnerabilities (36 total, page 1 of 2)

Severity CVE ID Summary CVSS Published
HIGH CVE-2026-77256 MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the plaintext OAuth fallback file containing refresh and access tokens is written with permissions inherited from the process umask. Under common or permissive configurations, other local users can read the backup and retain Atlassian access through the refresh token. The advisory traces the vulnerable input and processing flow through OAuthConfig._save_tokens_to_file, refresh_to -- Sep 22, 2026 CRITICAL CVE-2026-77254 MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, requests to the HTTP MCP endpoint without a per-user identity are allowed to reach tool handlers, which then use globally configured Jira or Confluence credentials. A network caller can perform operations with the operator account's permissions unless the deployment has an independent authentication boundary. The advisory traces the vulnerable input and processing flow through st 9.1 Sep 22, 2026 HIGH CVE-2026-77248 MCP Atlassian: Unauthenticated arbitrary local file read via upload_attachment file_path, chained with missing auth on streamable-http transport 8.6 Sep 22, 2026 HIGH CVE-2026-77246 MCP Atlassian: MCP HTTP Client Server-Local File Exfiltration via Unvalidated Attachment Upload Path 7.4 Sep 22, 2026 HIGH CVE-2026-77253 MCP Atlassian: Jira and Confluence attachment upload tools can read arbitrary server-local files 7.1 Sep 22, 2026 HIGH CVE-2026-77255 MCP Atlassian: Arbitrary File Read & Exfiltration (Confused Deputy) in JIRA update_issue 8.6 Sep 22, 2026 HIGH CVE-2026-77257 MCP Atlassian: HTTP upload tools accept arbitrary server-local file paths -- Sep 22, 2026 MEDIUM CVE-2026-77269 MCP Atlassian: Path traversal in upload_attachment allows arbitrary file read (incomplete fix for CVE-2026-27825) 6.5 Sep 22, 2026 MEDIUM CVE-2026-77266 MCP Atlassian: Path traversal in upload_attachment allows arbitrary file read and exfiltration via MCP tool call 6.5 Sep 22, 2026 HIGH CVE-2026-77259 MCP Atlassian: Arbitrary file read via confluence_upload_attachment allows exfiltration of server credentials 7.7 Sep 22, 2026 MEDIUM CVE-2026-77268 MCP Atlassian: Insecure File Permissions on OAuth Token Storage 5.5 Sep 22, 2026 HIGH CVE-2026-77262 MCP Atlassian: Path Traversal / Arbitrary File Read in confluence_upload_attachment MCP tool (incomplete fix of GHSA-xjgw-4wvw-rgm4) 8.6 Sep 22, 2026 MEDIUM CVE-2026-77272 MCP Atlassian: Reflected XSS in OAuth Setup Callback Handler 5.4 Sep 22, 2026 HIGH CVE-2026-77247 MCP Atlassian: Arbitrary server-local file upload to Jira/Confluence attachments via unrestricted file_path parameters -- Sep 22, 2026 MEDIUM CVE-2026-77249 MCP Atlassian: Incomplete fix for GHSA-7r34-79r5-rcc9: redirect-based SSRF via unhooked requests session in Jira user-permission lookup 5.3 Sep 22, 2026 HIGH CVE-2026-77271 MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, validate_safe_path defaults its base directory to os.getcwd(), and affected Confluence attachment call sites omit base_dir, allowing attacker-selected writes within the working directory. This Python module overwrite can provide code execution when the application later imports the modified module, bypassing the remediation tracked as CVE-2026-27825. This issue is fixed in versio -- Sep 22, 2026 HIGH CVE-2026-77251 MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, Jira search accepts a forbidden project clause because it checks only for the presence of project syntax, Confluence search uses an incomplete case-sensitive space check, and Jira board APIs omit project-filter enforcement. These paths expose issues, boards, or pages outside JIRA_PROJECTS_FILTER or CONFLUENCE_SPACES_FILTER when the operator credentials have broader access. The ad -- Sep 22, 2026 MEDIUM CVE-2026-77252 MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, caller-supplied projects_filter and spaces_filter arguments can replace administrator-configured allowlists, and caller-provided project or space clauses can suppress the configured restriction. A caller can search projects or spaces outside the intended boundary when the configured Atlassian credentials can access them. The advisory traces the vulnerable input and processing flo 6.5 Sep 22, 2026 HIGH CVE-2026-77243 MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, ENABLED_TOOLS and TOOLSETS are applied when tools are listed but are not rechecked when a tools/call request is dispatched. A client that knows a hidden tool name can directly invoke excluded read, write, or delete tools despite the operator's configured least-privilege restrictions. The advisory traces the vulnerable input and processing flow through ENABLED_TOOLS, TOOLSETS, too 8.8 Sep 22, 2026 HIGH CVE-2026-77267 MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the X-Atlassian-Jira-Url and X-Atlassian-Confluence-Url headers are processed by _process_authentication_headers and used to construct Atlassian fetchers without calling validate_url_for_ssrf. A caller who can set these headers can supply an internal or metadata-service URL and cause the server to send requests to that destination, bypassing the incomplete CVE-2026-27826 remediat -- Sep 22, 2026 HIGH CVE-2026-77261 MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, _make_ssrf_safe_hook is omitted from JiraFetcher and ConfluenceFetcher sessions created through the basic-auth and oauth_pat branches. If an attacker-controlled or compromised configured Atlassian instance returns a redirect to an internal address, those sessions can follow the redirect without revalidating its destination. This issue is fixed in version 0.22.0. 7.1 Sep 22, 2026 HIGH CVE-2026-77260 MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the Confluence and Jira upload_attachment implementations accept an unconstrained file_path and open the referenced server-local file. A permitted MCP caller can upload sensitive host files to an Atlassian destination and then retrieve their contents. The advisory traces the vulnerable input and processing flow through upload_attachment, file_path, and CVE-2026-27825, which ident -- Sep 22, 2026 HIGH CVE-2026-77242 MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, validate_url_for_ssrf checks a hostname's resolved addresses, but Requests and urllib3 resolve the hostname again when connecting. A caller can use a short-lived DNS answer that is public during validation and private during connection, preserving unauthenticated access to internal or metadata endpoints despite the earlier CVE-2026-27826 remediation. The advisory traces the vulne 7.5 Sep 22, 2026 MEDIUM CVE-2026-77250 MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, OAuthConfig writes a plaintext fallback file containing access and refresh tokens under the user's .mcp-atlassian directory using process-default permissions. On systems with a permissive umask, same-group or other local users and processes can read the persisted tokens and reuse the associated Atlassian access. The advisory traces the vulnerable input and processing flow through 6.1 Sep 22, 2026 MEDIUM CVE-2026-77270 MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the Jira and Confluence attachment upload tools treat caller-controlled file_path values as trusted server-local paths. The server opens the selected file and uploads it to an Atlassian issue or page, allowing an MCP caller with upload access to disclose any file readable by the server process. The advisory traces the vulnerable input and processing flow through confluence_upload 6.5 Sep 22, 2026

Showing 1–25 of 36

Frequently asked questions

What is MCP Atlassian?

MCP Atlassian is an AI/ML ai agents tracked by AI Threat Alert for security vulnerabilities in the pip ecosystem.

How many known vulnerabilities does MCP Atlassian have?

MCP Atlassian has 39 known CVEs, 3 of them critical, tracked from NVD and GitHub Advisory.

Which ecosystem is MCP Atlassian distributed in?

MCP Atlassian is distributed via the pip ecosystem and categorized as ai agents.

Where does the MCP Atlassian vulnerability data come from?

Vulnerability data is sourced from NVD and GitHub Advisory, enriched with CVSS, EPSS, exploit signals, and patch status for each CVE.

How do I assess the risk of MCP Atlassian?

Review each CVE below — every entry shows CVSS severity, EPSS exploit probability, exploitation signals, and whether a patched version is available.

Monitor MCP Atlassian in your stack

Get instant alerts when new vulnerabilities affect MCP Atlassian. CISO analysis, ATLAS technique mappings, and compliance reports included.

Start Monitoring